• Three security vulnerabilities have been disclosed in the Peripheral Component Interconnect Express (PCIe) Integrity and Data Encryption (IDE) protocol specification that could expose a local attacker to serious risks. The flaws impact PCIe Base Specification Revision 5.0 and onwards in the protocol mechanism introduced by the IDE Engineering Change Notice (ECN), according to the PCI Special

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a security flaw impacting the WinRAR file archiver and compression utility to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2025-6218 (CVSS score: 7.8), is a path traversal bug that could enable code execution. However, for exploitation

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cloud security is changing. Attackers are no longer just breaking down the door; they are finding unlocked windows in your configurations, your identities, and your code. Standard security tools often miss these threats because they look like normal activity. To stop them, you need to see exactly how these attacks happen in the real world. Next week, the Cortex Cloud team at Palo Alto Networks

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft closed out 2025 with patches for 56 security flaws in various products across the Windows platform, including one vulnerability that has been actively exploited in the wild. Of the 56 flaws, three are rated Critical, and 53 are rated Important in severity. Two other defects are listed as publicly known at the time of the release. These include 29 privilege escalation, 18 remote code

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Fortinet, Ivanti, and SAP have moved to address critical security flaws in their products that, if successfully exploited, could result in an authentication bypass and code execution. The Fortinet vulnerabilities affect FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager and relate to a case of improper verification of a cryptographic signature. They are tracked as CVE-2025-59718 and

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft today pushed updates to fix at least 56 security flaws in its Windows operating systems and supported software. This final Patch Tuesday of 2025 tackles one zero-day bug that is already being exploited, as well as two publicly disclosed vulnerabilities.

    Despite releasing a lower-than-normal number of security updates these past few months, Microsoft patched a whopping 1,129 vulnerabilities in 2025, an 11.9% increase from 2024. According to Satnam Narang at Tenable, this year marks the second consecutive year that Microsoft patched over one thousand vulnerabilities, and the third time it has done so since its inception.

    The zero-day flaw patched today is CVE-2025-62221, a privilege escalation vulnerability affecting Windows 10 and later editions. The weakness resides in a component called the “Windows Cloud Files Mini Filter Driver” — a system driver that enables cloud applications to access file system functionalities.

    “This is particularly concerning, as the mini filter is integral to services like OneDrive, Google Drive, and iCloud, and remains a core Windows component, even if none of those apps were installed,” said Adam Barnett, lead software engineer at Rapid7.

    Only three of the flaws patched today earned Microsoft’s most-dire “critical” rating: Both CVE-2025-62554 and CVE-2025-62557 involve Microsoft Office, and both can exploited merely by viewing a booby-trapped email message in the Preview Pane. Another critical bug — CVE-2025-62562 — involves Microsoft Outlook, although Redmond says the Preview Pane is not an attack vector with this one.

    But according to Microsoft, the vulnerabilities most likely to be exploited from this month’s patch batch are other (non-critical) privilege escalation bugs, including:

    CVE-2025-62458 — Win32k
    CVE-2025-62470 — Windows Common Log File System Driver
    CVE-2025-62472 — Windows Remote Access Connection Manager
    CVE-2025-59516 — Windows Storage VSP Driver
    CVE-2025-59517 — Windows Storage VSP Driver

    Kev Breen, senior director of threat research at Immersive, said privilege escalation flaws are observed in almost every incident involving host compromises.

    “We don’t know why Microsoft has marked these specifically as more likely, but the majority of these components have historically been exploited in the wild or have enough technical detail on previous CVEs that it would be easier for threat actors to weaponize these,” Breen said. “Either way, while not actively being exploited, these should be patched sooner rather than later.”

    One of the more interesting vulnerabilities patched this month is CVE-2025-64671, a remote code execution flaw in the Github Copilot Plugin for Jetbrains AI-based coding assistant that is used by Microsoft and GitHub. Breen said this flaw would allow attackers to execute arbitrary code by tricking the large language model (LLM) into running commands that bypass the user’s “auto-approve” settings.

    CVE-2025-64671 is part of a broader, more systemic security crisis that security researcher Ari Marzuk has branded IDEsaster (IDE  stands for “integrated development environment”), which encompasses more than 30 separate vulnerabilities reported in nearly a dozen market-leading AI coding platforms, including Cursor, Windsurf, Gemini CLI, and Claude Code.

    The other publicly-disclosed vulnerability patched today is CVE-2025-54100, a remote code execution bug in Windows Powershell on Windows Server 2008 and later that allows an unauthenticated attacker to run code in the security context of the user.

    For anyone seeking a more granular breakdown of the security updates Microsoft pushed today, check out the roundup at the SANS Internet Storm Center. As always, please leave a note in the comments if you experience problems applying any of this month’s Windows patches.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Congress is committing to only a fraction of the funding necessary for the Navy’s F/A-XX program in the latest version of the defense policy bill, while fully backing the development of the Air Force’s F-47 fighter.

    The compromise version of the 2026 National Defense Authorization Act released late Sunday evening contains roughly $2.6 billion for the Air Force’s F-47 program, and just $74 million to develop the Navy’s unnamed sixth-generation fighter jet. The numbers appear to reflect a White House and Pentagon victory over lawmakers who pushed to get the long-proposed replacement for the F/A-18 Super Hornet and F/A-18 electronic-warfare jet onto the drawing board this year. 

    “We did make a strategic decision to go all in on F-47…due to our belief that the industrial base can only handle going fast on one program at this time, and the presidential priority to go all in on F-47 and get that program right while maintaining the option for F/A-XX in the future,” a U.S. defense official told reporters during a June budget rollout. 

    The F/A-XX will receive less than 1 percent of the $38 billion that the NDAA would authorize to develop, buy, and upgrade military aircraft, according to the House majority’s summary of the bill. Still, the 2026 appropriations bill has yet to emerge, the reconciliation bill might add funds, and the program might also, as it has in the past, receive funds through classified accounts.

    A House Armed Services Committee spokesperson did not immediately respond to clarifications regarding the total amount of funding for the program.

    In March, the Navy reportedly came close to choosing Boeing or Northrop Grumman to make the future aircraft. But no announcement was made, and the service requested only $74 million for 2026, far less than the $454 million the service received last year.

    Defense Secretary Pete Hegseth has echoed the White House’s concerns about pursuing the Navy’s future fighter, reportedly telling lawmakers in a November letter that the Pentagon “strongly supports its original fiscal 2026 request reevaluating the F/A-XX program due to industrial base concerns of two sixth-generation programs occurring simultaneously.”

    Several lawmakers, including Sen. Mitch McConnell, R-Ky. have been vocal about their desire to keep the program moving.

    “Pentagon dithering over the Navy’s sixth-generation fighter, the F/A-XX, has delayed its development and led to hundreds of millions in contract-extension costs,” McConnell wrote last week in a Wall Street Journal opinion piece. “If the department made a decision, Mr. Trump could launch a program that ensures the aircraft carrier remains America’s premier power-projection platform for decades.”

    The final funding amount for the Navy’s future fighter is still up in the air. In July, the House passed its version of the 2026 defense appropriations bill with $972 million for the F/A-XX. 

    “The Committee understands the Navy’s requirement for a sixth-generation fighter remains unchanged and emphatically notes that the Air Force’s F-47 program is not interchangeable with Navy’s carrier-capable program,” House appropriators wrote, adding that “both programs are necessary parts of the future joint fight and failure to pursue Navy’s F/A-XX program risks leaving the U.S. dangerously outmatched in a high-end conflict.”

    Reconciliation funding passed that same month included $750 million to “accelerate the FA/XX aircraft.” The full Senate has yet to vote on its version of the appropriations bill, which includes $1.4 billion for it.

    The Senate version of the authorization bill reportedly included $500 million for F/A-XX through a special access program known as “Link Plumeria,” which has been previously tied to the Navy’s next-generation fighter efforts. The compromise NDAA identified $377 million for “Link Plumeria.”

    As for the F-47: lawmakers are funding it yet but still want answers to basic questions.

    The compromise NDAA requests a report on the F-47 program with details about “projected costs, schedule, and funding requirements” through 2034. Lawmakers are also requesting details on the estimated force structure requirements, strategic basing considerations, construction costs, personnel training requirements, and a strategy for integrating Air National Guard and Air Force Reserve units into the future fighter’s operations. 

    The Air Force Secretary must provide those findings by March 1, 2027. The jet is is expected to make its first flight in 2028.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Updated on Dec. 10.

    With its calls for “strong, traditional families” and the “reinvigoration of American spiritual and cultural health,” the latest National Security Strategy is a major departure not only from its immediate predecessor, but even the first Trump administration’s.

    A longer version of the NSS that circulated before the White House published the unclassified version late Thursday night shares the main points: competition with China, withdrawal from Europe’s defense, a new focus on the Western Hemisphere. But the unpublished version also proposes new vehicles for leadership on the world stage and a different way to put its thumb on the scales of Europe’s future—through its cultural values.

    Here are some takeaways from the unpublished version, which was reviewed by Defense One

    “Make Europe Great Again”

    While the publicly released NSS calls for the end of a “perpetually expanding NATO,” the full version goes more into the details of how the Trump administration would like to—quote—“Make Europe Great Again,” even as it calls on European NATO members to wean themselves from American military support.

    Working from the premise that Europe is facing “civilizational erasure” because of its immigration policies and “censorship of free speech,” the NSS proposes to focus U.S. relationships with European countries on a few nations with like-minded—right-wing, presumably—current administrations and movements.

    Austria, Hungary, Italy, and Poland are listed as countries the U.S. should “work more with…with the goal of pulling them away from the [European Union].”

    “And we should support parties, movements, and intellectual and cultural figures who seek sovereignty and preservation/restoration of traditional European ways of life…while remaining pro-American,” the document says.

    The C5

    Over the summer, President Trump made headlines when he lamented the expulsion of Russia from the Group of Eight—now the Group of Seven—as  a “very big mistake.” He even suggested that he’d like to see China added  to form a “G9.”

    His national security strategy proposes taking this a step further, creating a new body of major powers, one that isn’t hemmed in by the G7’s requirements that the countries be both wealthy and democratically governed.

    The strategy proposes a “Core 5,” or C5, made up of the U.S., China, Russia, India and Japan—which are several of the countries with more than 100 million people. It would meet regularly, as the G7 does, for summits with specific themes.

    First on the C5’s proposed agenda: Middle East security—specifically, normalizing relations between Israel and Saudi Arabia. 

    “Hegemony wasn’t achievable”

    The full NSS also spends some time discussing the “failure” of American hegemony, a term that isn’t mentioned in the publicly released version.

    “Hegemony is the wrong thing to want and it wasn’t achievable,” according to the document. 

    In this context, hegemony refers to the leadership by one country of the world, using soft power to encourage other countries to consent to being led. 

    “After the end of the Cold War, American foreign policy elites convinced themselves that permanent American domination of the entire world was in the best interests of our country,” the NSS states. “Yet the affairs of other countries are our concern only if their activities directly threaten our interests.”

    The administration appears to be using this reasoning to bow out of the U.S.’s role in defending Europe, while turning its attention to Venezuela-based drug cartels.

    “The Trump administration inherited a world in which the guns of war have shattered the peace and stability of many countries on many continents,” the NSS reads. “We have a natural interest in ameliorating this crisis.”

    The document says it shouldn’t be up to the United States to do it all alone—but also, China and Russia should not be allowed to replace U.S. leadership. The strategy suggests partnering with “regional champions” to help maintain stability.

    “We will reward and encourage the region’s governments, political parties, and movements broadly aligned with our principles and strategy,” according to the document. “But we must not overlook governments with different outlooks with whom we nonetheless share interests and who want to work with us.”

    After this story was published, the White House denied the existence of any version of the National Security Strategy other than the one published online.

    “No alternative, private, or classified version exists,” spokeswoman Anna Kelly told Defense One. “President Trump is transparent and put his signature on one NSS that clearly instructs the U.S. government to execute on his defined principles and priorities.”

    Kelly then added that “any other so-called ‘versions’ are leaked by people distant from the President who, like this ‘reporter,’ have no idea what they are talking about.’ ”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Threat actors with ties to North Korea have likely become the latest to exploit the recently disclosed critical React2Shell security flaw in React Server Components (RSC) to deliver a previously undocumented remote access trojan dubbed EtherRAT. “EtherRAT leverages Ethereum smart contracts for command-and-control (C2) resolution, deploys five independent Linux persistence mechanisms, and

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Five days after President Trump said he was ok with releasing video of the U.S. military’s first attack on alleged drug trafficking boats off the Latin American coast, he backed away from that pledge Monday, telling reporters he’d let his embattled Pentagon chief Pete Hegseth decide. 

    Dec. 3: “I don’t know what they have, but whatever they have, we’d certainly release. No problem,” Trump told reporters (read a transcript via Roll Call, here). 

    Dec. 8: On Monday, a reporter asked the president if he still felt that way. “Mr. President, you said you would have no problem with releasing the full video of that strike on Sept. 2 off the coast of Venezuela. Secretary Hegseth now says—” the reporter said before the president interrupted her. 

    “I didn’t say that. You said that. I didn’t say that,” Trump responded. “This is ABC fake news. I said, whatever Hegseth wants to do is OK with me.”

    SecDef Hegseth’s latest position: “Whatever we were to decide to release, we’d have to be very responsible” about it, he said Saturday on the sidelines of the annual Reagan National Defense Forum in California. 

    Why it matters: The strike in question reportedly killed two survivors aboard the boat on Sept. 2, according to the Washington Post, which noted the operation was carried out on Hegseth’s orders. “I watched it live,” the secretary told Fox the following day. But he changed his account after details of the operation became public. Last week, the Pentagon chief told reporters that he “watched that first strike live” but “didn’t stick around” for subsequent strikes. In the days since, several lawmakers have called for the release of surveillance footage of the attacks, which the Post reports involved four strikes in total: “twice to kill the crew and twice more to sink it.” 

    Killing survivors of a strike at sea could be a violation of the laws of war, multiple legal experts have argued since the Post published its report just after Thanksgiving.

    Lawmakers of both parties want the public to see the videos, and are planning to withhold one-quarter of Hegseth’s travel budget until he releases them, Politico reported Monday after House and Senate negotiators agreed on a compromise version of the 2026 defense policy bill (PDF). House lawmakers are expected to approve the final draft this week, with Senate approval expected shortly afterward. 

    Also included in the pending NDAA: 

    • $400 billion for Ukraine through a provision to pay U.S. companies for the sale of weapons to Kyiv; 
    • $175 million to help boost Latvia, Lithuania and Estonia's defense against Russian aggression; 
    • $200 million for Israeli missile defense as well as $80 million for anti-tunneling operations and $70 million for joint counter-drone programs;
    • $1 billion intended for Taiwan's military to help defend against a possible Chinese attack or invasion; 
    • $1.5 billion in support for the Philippines; 
    • And 4% pay raise for U.S. troops. 

    Notably, the NDAA does not fund Trump’s plan to rename the Defense Department to the “Department of War,” which NBC News reported last month is estimated to cost $2 billion. (Hat tip to Reuters.)

    Additional reading: 

    Coverage continues below…


    Welcome to this Tuesday edition of The D Brief, a newsletter dedicated to developments affecting the future of U.S. national security, brought to you by Ben Watson and Bradley Peniston. It’s more important than ever to stay informed, so thank you for reading. Share your tips and feedback here. And if you’re not already subscribed, you can do that here. On this day in 1938, the first operational shipboard radar was installed aboard the battleship USS New York.

    Developing: The Pentagon will widely deploy new AI tools for logistics, intelligence analysis, and combat planning in mere days or weeks, its research-and-engineering chief said Monday, adding that wide deployment of artificial intelligence now tops his list of “critical technologies,” Defense One’s Patrick Tucker reports

    The department has chosen Gemini for Government as the platform that will support DOD’s first department-wide rollout of AI tools, Google and defense officials announced Tuesday morning. The moves come after the Defense Innovation Unit, the Chief Digital and Artificial Intelligence Office, or CDAO, and others were combined under Emil Michael, defense undersecretary for research and engineering, in a bid to accelerate deployment of AI and other technologies. He said that he will likely reduce the number of technology areas that DIU is working on as well.

    The advent of large-language-model tools such as ChatGPT, Claude, and Gemini have made it possible—and necessary—to develop AI tools faster, Michael told reporters at the Defense Writers Group on Monday. “The explosion of capabilities has been enormous, and we're just catching up to that,” he said. “Now we can take CDAO and actually try to use it to push the capability into the Department for actual use cases.” Read more, here

    Big-picture analysis: The U.S. military needs to reinvent itself to deter future wars, the New York Times editorial board argues in a new roundup of many national security dynamics Defense One readers will be probably familiar with. A few of the more salient points include the following reminders: 

    • The Pentagon has an “overreliance on expensive, vulnerable weapons as adversaries field cheap, technologically advanced ones.”
    • “An entrenched oligopoly of five large defense contractors, down from 51 in the early 1990s, has an interest in selling the Pentagon ever-costlier evolutions of the same ships, planes and missiles.”
    • The “Ford [carrier], which is currently deployed in the Caribbean, is fatally vulnerable to new forms of attack. China in recent years has amassed an arsenal of around 600 hypersonic weapons, which can travel at five times the speed of sound and are difficult to intercept. Other countries possess quiet diesel-electric submarines capable of sinking American carriers.”
    • And as the latest NDAA makes its way through congress, the Times editorial board notes “The Trump administration wants to increase defense spending in 2026 to more than $1 trillion. Much of that money will be squandered on capabilities that do more to magnify our weaknesses than to sharpen our strengths.”

    “This is the first of a series of editorials examining what’s gone wrong with the U.S. military—technologically, bureaucratically, culturally, politically and strategically,” the Times writes. Read the rest, here

    Additional reading: 

    • Tom Wright of Brookings argues the White House’s new strategy “Ignores the Real Threats” facing the U.S., including “silen[ce] on Beijing’s ambition to displace Washington as the world’s leading power,” and “nothing about the Russian threat to U.S. interests.” Read his Monday response in The Atlantic, here.
    • See also “The Origin of Hegseth’s Anti-Beard Obsession,” via former Pentagon official Alex Wagner, writing Saturday in The Atlantic;
    • And “General Dynamics wants to turn competitors into teammates,” Defense One’s Lauren C. Williams reported Monday. 

    Trump 2.0

    “Worst of the Worst” site skips evidence. A new Department of Homeland Security website purports to list the worst “criminal aliens” arrested by ICE. The website names more than 9,800 of the “hundreds of thousands” of people taken into custody by Immigration and Customs Enforcement in the past 11 months. Each name is presented, information-card style, with their countries of origin and one or more alleged crimes. Most include a formal or informal mug shot; some, oddly, do not.

    For the vast majority of people, no corroboration is given of their purported criminality. Among the first 1,200 names, just 4% link to DHS press releases; no other kind of documentation is offered. (The site is “all about transparency,” a DHS spokesperson said in a press release.)

    Best of the worst of the worst? Many of the names are listed with one or more awful crimes: homicide, sexual assault, human trafficking, and more. But the sample also includes more than a handful of people whose only listed crimes were far more minor: shoplifting, marijuana possession, traffic offenses. Nearly 5% were accused solely of (felony) illegal re-entry.

    Finally, more than two dozen names have quietly been removed from the site since it went up on Monday, according to a Defense One analysis of the site. No explanation is given. 

    Most people arrested by ICE this year had no criminal record at all, Axios reported last week off a new tranche of data released by the agency. That wasn’t the case until May, when the White House reportedly ordered ICE to triple its daily quota of arrests from 1,000 to 3,000. “Now, agents have a broader mandate and have been encouraged to make more ‘collateral arrests,’ apprehending undocumented people who happen to be with someone on a target list, such as people in the same household,” Axios wrote.

    That’s especially true in Washington, D.C., the first city to see an unprecedented deployment of federal troops under Trump. “More than 80 percent of the immigrants arrested in D.C. during the surge in federal law enforcement this year had no prior criminal record,” the Washington Post reported on Thursday. 

    “The new data confirms that the Trump administration isn't focused on legitimate public safety risks, but rather on hitting politically motivated arrest targets,” Aaron Reichlin-Melnick, senior fellow at the American Immigration Council, told Axios last week.

    Related reading: 

    Additional reading:  

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶